Articles in the CA Security Advisor Category

Win32/Sdbot.ADG!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/SDBot is a multi-component IRC bot controlled Worm designed to exploit known system vulnerabilities in order to propagate across a network.

 

Win32/Delf.ALY
Posted in CA Security Advisor on 8 June 2011

Win32/Delf is a multi-component family of Trojan generally characterize as Delphi-compiled threats capable to drop, download and install other malicious files.

 

Win32/Rimecud.CWB!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Rimecud is a family of self-replicating programs that propagate via removable drives, MSN Instant Messenger and P2P (peer-to-peer) shared folders. Variants of this family also have the capability to steal information from the infected system. Furthermore, Win32/Rimecud propagates via removable disk drives such as USB drives. It also drops “Autorun.inf” and a randomly-named copy of itself to…

 

Win32/Ransom.QI!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Ransom is CA?s generic detection name for family of ransomware. Ransomware is a computer malware that poses security threat by encrypting user’s data and taking full control of the machine. It often demands certain amount money to restore encrypted files and unlock the victim’s machine.

 

Win32/Rbot.ZUD!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Rbot is an IRC controlled backdoor (or “bot”) that can be used to gain unauthorized access to a victim’s machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is…

 

Win32/QQPass.NWZ!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/QQPass is a family of password stealing Trojans for application such as Tencent QQToolBar.

 

Win32/Qakbot.JO!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Qakbot is a family of Trojan that downloads other malicious components onto the system and has the capability to communicate to an IRC command and control server. Some variants of this malware family can also spread to other machines via network shares.

 

Win32/Palevo.LP!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Palevo is family of network-aware worms that propagate via removable drives, MSN, Yahoo and Skype instant messaging applications and P2P (peer-to-peer) shared folders. Variants of this family also have the capability to steal information from the infected system and participate in a distributed denial of service (DDoS) attacks.

 

Win32/PCClient.BHY!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Pcclient is a family of backdoor trojans, controlled through outgoing HTTP connections.

 

Win32/Oficla.XY!suspicious
Posted in CA Security Advisor on 8 June 2011

Win32/Oficla is a family of Trojans that downloads other malicious files from the Internet.